Summary
CVE-2026-62586 is a vulnerability in the Data Archival component of Oracle Siebel CRM Administration that allows an unauthenticated, remote attacker to gain unauthorized access to critical data over HTTP. Oracle rates the issue 8.6 (HIGH) under CVSS v3.1, and it is described as easily exploitable, requiring no privileges or user interaction. Successful exploitation results in complete disclosure of accessible Siebel CRM Administration data, with potential impact to additional products.
Technical details
- Root cause: a flaw in the Data Archival component of Siebel CRM Administration.
- Trigger conditions: no authentication or user interaction is required to exploit the vulnerability.
- Attack vector: network access via the HTTP protocol.
- Impact: unauthorized access to and complete disclosure of critical data accessible to Siebel CRM Administration; the CVSS scope is rated as "Changed," indicating impact may extend beyond the vulnerable component to other products.
Affected software
- Oracle Siebel CRM Administration versions 25.12 through 26.6.
Severity
- CVSS v3.1 Base Score: 8.6 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update (Security Alert CSPU Aug 2026) for all Siebel CRM Administration deployments running versions 25.12 through 26.6.
- If patching cannot be applied immediately: restrict network access to Siebel CRM Administration interfaces (e.g., via firewall rules, VPN, or access control lists) to trusted internal networks only, and monitor HTTP access logs for anomalous or unauthenticated requests to Data Archival endpoints until the patch can be applied.

